Back to skill

Security audit

Poly Master

Security checks for vulnerabilities and agentic risk

Overview

This real-money Polymarket trading skill is mostly coherent, but its hedge-trading and copy-trading instructions are inconsistent enough that users should review it carefully before installing.

Install only if you intentionally want an agent connected to Polymarket trading workflows. Treat all order links, copy-trading settings, and hedge signals as real financial actions that can lose funds; verify every wallet signing page yourself. Be especially cautious with hedge execution claims and ask the publisher to clarify whether hedge execution and copy-trading require explicit confirmation for each order, how to revoke stored agent credentials, and how wallet/profile data is retained or shared.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly states that hedge execution is not available via MCP, but later defines a mandatory two-leg hedge execution output format that reads like supported operational guidance. This inconsistency can cause an agent to present or attempt unsupported multi-leg trade execution flows, increasing the chance of misleading users into signing unintended live orders or relying on nonexistent safety guarantees for a coordinated hedge.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest uses very broad triggers such as 'poly', 'smart money', 'arbitrage', and multilingual generic finance terms, which can cause the skill to activate for unrelated user requests. In a live trading skill, overbroad invocation is dangerous because it can pull the agent into high-risk financial workflows when the user did not intend to access order-placement or wallet-linked functionality.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The description promotes investing, copy-trading, and arbitrage features without an upfront warning that actions may place real market orders affecting user funds. In this context, lack of a prominent transactional risk warning increases the likelihood that users engage with the skill as if it were informational only, despite it being capable of initiating live order-signing flows.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The quickstart actively guides users through buying, selling, copy-trading, and executing hedge strategies, including claims of 'near-riskless arbitrage,' but does not prominently warn that users can lose funds, face slippage, market resolution risk, liquidity risk, or execution failure. In a trading skill, omission of clear financial risk disclosure can mislead users into treating speculative or multi-leg strategies as safe, increasing the chance of harmful financial decisions.

Missing User Warnings

Low
Confidence
82% confidence
Finding
The guide explains wallet profiling, top-holder analysis, portfolio views, and trader-following without telling users what wallet/trading data is collected, cached, enriched, or exposed through third-party services such as Antalpha components. In a financial context, undocumented data use can create privacy surprises, compliance issues, and unsafe assumptions about how on-chain identities and portfolio information are handled.

Static analysis

No suspicious patterns detected.